Skip to main content
Loading…
    CVE-2026-35056 — XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server. — CVE Database · The Intelligence Room